Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2021-3427

Опубликовано: 26 авг. 2022
Источник: debian
EPSS Низкий

Описание

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
delugefixed2.1.1-1experimentalpackage
delugefixed2.1.1-4package
delugeno-dsabookwormpackage
delugeno-dsabullseyepackage
delugeno-dsabusterpackage

Примечания

  • https://dev.deluge-torrent.org/ticket/3459

  • https://dev.deluge-torrent.org/changeset/8ece03677

  • https://dev.deluge-torrent.org/changeset/a5503c0c606

EPSS

Процентиль: 70%
0.00632
Низкий

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 3 лет назад

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

CVSS3: 6.1
nvd
больше 3 лет назад

The Deluge Web-UI is vulnerable to XSS through a crafted torrent file. The the data from torrent files is not properly sanitised as it's interpreted directly as HTML. Someone who supplies the user with a malicious torrent file can execute arbitrary Javascript code in the context of the user's browser session.

CVSS3: 6.1
github
больше 3 лет назад

Deluge Web-UI vulnerable to XSS through a crafted torrent file

EPSS

Процентиль: 70%
0.00632
Низкий